The People’s Code
whitehouse.gov
whitehouse.gov
This is a great move by the White House. While there are a lot of groups that are trying to push for more openness and release of software, it can often be challenging. A lot of federal groups have been taught over the years to be very risk averse, and open software is viewed by them to be risk. Probably one of the most common concerns is, "What happens if someone takes and misuses our software?" In a highly risk-averse federal environment, these can be challenging arguments to fight against.
If you like and support this kind of thing, one big thing you can do is to contribute and supply feedback. We frequently have to go to our superiors and justify what we are doing with regards to open source. We say things like, "this repository had X pull requests from non-federal contributors". Or, "We got Y comments and questions from non-federal users of our projects".
It could be as simple as an email saying "Hey thanks, I found this useful", to a full-on pull request fixing an issue or with a new feature request. The more fodder we have to say "open source increases engagement and creates positive feedback" the more you will see this kind of thing happening.
Shrinkwrapped software != bespoke software that is contracted to be developed for the government
IMO any software that is contracted to be developed by the government should be public domain, if the government "owns" the software then in reality the public "owns" it... after all the government is "for the people, by the people" right...
This does preclude the government from licensing the USE of software (like Windows, Office, etc) that is a completely different debate. However if the government is contracting with a company for the company to build custom software the exclusive use of the government they yes that should be Public domain.
But that doesn't mean it has to be hosted and released online. Many agencies work under the "not going to release anything until we get a FOIA request" model. Just because it is public domain doesn't mean it is public.
I realize that setting up an automatic integration between your existing source control system and github might be nontrivial (eg if you are using an unpopular source control system for which no easy conversion to git) so this won't work for everyone without funding (and it would be nice if some were made available for that)
But if you already use git (or something like SVN or hg which can easily interoperate with git) or don't currently use any SCM (!) then just publishing to github is a nobrainer.
Am I missing anything?
Of course, the last one is the worst. A lot of groups are getting their act together when it comes to starting open-source, but it is met with a lot of skepticism.
How can you (or we) ensure your FOIA request for code isn't responded to with a PDF of code?
Overall I think the FOIA is a great utility. Most big name federal agencies actually have FOIA liaisons that will try to help if they can. Some, of course, are just as douche-y as you would imagine (e.g. NSA, NRO, CIA). Though I did have a few good interactions with CIA FOIAs, mostly bad ones though. The FOIA actually says in the law that the reviewing official should look at a FOIA as "what can we release?" and not as "what can we hide?", and you need to tell people this more often than you would like. I actually used a FOIA to get my DNA information from the military's secret-but-not-secret DNA database. It's a database of every service member's DNA, and ostensibly is for identifying remains. That was actually very difficult, because nobody had ever FOIA'ed the Army's "funerary affairs" office for DNA information, and so they were under the impression they could just ignore my requests. That taught me a lot and was actually fun in a weird way. You just have to persist, and escalate if you don't agree with the response or don't get any. FOIAs are serious business, and most people in the US government are people just like you and me, and want to help you find what you're looking for. Though, some people in government -- like any other community -- are bullies on a power trip. Wow, sorry for the wall of text!
Apparently things are a bit more complicated than this, since works created by government employees are in the public domain in the US, but foreign copyrights are still held by the government. Unless the software is released with a FOSS license where applicable, I don't think public domain government code is compatible with other FOSS licenses (which are generally worldwide).
Even if it weren't the case that the US government held full copyrights abroad, it's still something of a problem because some jurisdictions do not have a concept of public domain - this is why the concept CC-0 licensing comes into play (it's public domain with a permissive license fallback).
See 18F's open source policy: https://github.com/18F/open-source-policy/blob/master/policy...
This "Federal Source Code" policy is a great extension of the project-open-data initiative released a few years back:
https://github.com/project-open-data
I found the db-to-api project in this repository incredibly useful for quickly and safely exposing data from one of my applications to clients.
The only failing I see to these many many initiatives is that so few people realize these powerful free resources are out there to be taken advantage of. I hope that changes in the future.
There are a number of open data reference lists (e.g. - health care facilities) that we are going to be able to snapshot from APIs, rather than maintaining them separately.
A good example, there's a recall API: https://github.com/GSA/recalls_api
this is cool, I want to use it... I have an eCommerce website where I sell food. It would be cool if I could be proactive in pulling items from my product catalog. The issue is there is no UPC in the API, so there's no easy way to correlate my products to recalled products. A cursory look at the source code shows me the source:
http://www.fda.gov/AboutFDA/ContactFDA/StayInformed/RSSFeeds...
if you open that up, a lot of the items have the UPC codes in there. This gives me the ability to parse the details, and add the fields I need.
Very nice; this is especially important for government sites. It's even printer-friendly out of the box!
http://assets.cms.gov/resources/framework/3.0/Pages/#documen...
?
(Which seems dormant/dead unfortunately).
I wonder how this will affect bids for government software projects? Will companies be upset that they have to open-source their software? Regardless of whether an individual agency will use it, I can see the initiative saving time and money, since programmers will know they can just find what they need in a repository. If there is one thing you can count on, it's programmers and government employees being lazy.
I can see the downsides though, like somebody publishing code with keys or credentials in it. That seems like a fairly likely error.
[1]: https://emanuelfeld.github.io/blog/2016/04/27/government-git...
[2]: https://18f.gsa.gov/2016/06/16/emanuel-feld-talks-about-his-...
I've been thinking this for a long time, and I'm pleasantly surprised that the US government now says this publicly. I hope this point of view becomes more prevalent in the near future.
For one, Pull Requests: If a government agency gets a PR on some code, I'm concerned there may be pressure not to accept it: auditing requirements that are so high that nobody wants to review PRs (not that audits are bad!), or policies that otherwise don't encourage PRs, meaning that improvements don't get back to the government.
Secondly, us winding up with a repeat of some of the problems that other previously proprietary projects (namely, OpenSolaris) encountered: The code that was opensourced being dependant on code that, for whatever reason, couldn't be opensourced, hampering forks, and further development outside of the organization that developed the software in the first place.
Even if issues like this, or issues that I haven't even thought of, occur, this is a huge step forward.
She told me that many departments who don't currently have much experience in open source express the concern that if they open source their code, they've got to deal with all the issues that come with maintainership of an open source project.
Her opinion, though, was that the first and foremost reason for encouraging agencies to release their code is transparency and accountability - it's taxpayer money, after all - and that even chucking up a plain old tarball is a great start. As for running an open source community - well, cross that bridge when you get to it. It's entirely possible that no-one actually cares about contributing to your codebase. It's entirely possible that you're not going to have to deal with contributions larger than typo fixes. If you do end up getting larger contributions, write your policy and your process when you need it.
If you're in the parts of government that are encouraging a move towards openness, tell other agencies that it's fine if they don't have a fully developed open source strategy. Get their code up on GitHub somewhere first, prove that the sky won't fall in, and just get them comfortable with the concept of open source. Once we've achieved the first objective of getting source code out in the open at all, then we can worry about the rest.
Indeed. And so are words like "homeland".
The last ~2 decades have seen a widespread change in ideas about the relationship between the U.S. federal govt. and the people. As a result, practices that were once restricted to highly repressive states are now merely a bit controversial in the U.S. And then we also have these ways of naming things that you & I noted.
So I wonder: could it be that thinking more like a totalitarian somehow naturally leads one to talk more like a totalitarian?
I think some people just like talking like that.
A definitional enemy. Very newspeak.
That's like saying straight people should refrain from using rainbows because they are used by the LGBT community.
We should look into solutions for intellectual property that are based on an information economy instead of an industrial economy.
Personally, I think it would make sense (perhaps more for pharmaceuticals than software) to significantly shorten the time a patent is valid and/or strip the protection of monopolistic production rights, and instead allow the free market to sell the product at the lowest cost it can be made at, as long as there is a royalty fee. How the fee is determined, I'm not sure yet.
Still, it's clear that our IP system is creaky, overcomplicated, and is tilted too far in the direction of big business, lawyers, and patent trolls, instead of the actual inventors and consumers.
If the issue is that inventors want to get compensated for their inventions (to a degree commensurate with their value), but we don't want to limit what the market can produce, then maybe we could imagine an IP-buying group that paid a fair price to inventors and then made the IP available for general use among the financial backers of said group. One could imagine this as a governmental function (distributing purchased IP among taxpayers) or a corporation (s/taxpayers/shareholders), and it appears to me[0] either one could fit within the framework of existing IP law.
[0] I am not a lawyer and have no idea if this is true.
TL;DR: The DOE encourages open source software, but it isn't default and there's some (low) barriers.
In general, though, what you can do with your (non-export-controlled) code consists of (in order of increasing difficulty):
1. Nothing. Keep your code private. If you'd like to stop maintaining code but want to make sure it sticks around, the DOE has a software library, the ESTSC, in Oak Ridge (a division of OSTI). It may also be the case that the entity running the lab wants to claim ownership.
2. Open Source. Due diligence is needed to ensure funding agencies and MOUs are respected. Copyright is typically assigned to the contractor running the lab in question (i.e. for Berkeley lab, -> Copyright goes to UC, SLAC -> Stanford, etc...). Major international collaborations can be a bit tricky because foreign countries have their own rules. I think more work needs to be emphasized on this front going forwards.
The DOE also wants to track the popularity of Open Source software, namely downloads. GitHub has met their requirements for reporting.
The DOE discourages use of the GPL and similar licenses. The reason, as I understand it, is due to the fact that the Government (i.e. Defense) must be able to use and modify software (and give to contractors, etc...) without falling under any additional burden. I believe the BSD license is preferred most widely across the labs.
In some cases, people at labs do release software under GPL. If they didn't get special permission, they are likely violating their lab's contract with the DOE.
3. Commercialize. This is really hard. You have to first perform market research, establish the market, spin off, deal with SBIRs, etc... This is a high barrier.
I've been personally working on streamlining the process for (2) with legal for my lab, so that anybody can open source their software very easily, hopefully by just filling out a web page. I'm hoping the recent white house directives help eliminate some of the bureaucracy involved in the process. I've also been trying to reduce fragmentation across the lab. The lab has never offered an official SCM platform, and grad students/postdocs are notoriously bad at keeping important source code in their personal GitHub and then leaving after some time.
It should be noted that almost all national lab facilities are effectively ran under contract, so nearly all national lab employees are not actually federal employees. So we do have a slightly different set of rules.
Finally, there is already a decent presence on github and bitbucket of labs, in case you are interested:
https://bitbucket.org/berkeleylab/
It should be noted this is an extremely, extremely small slice of the software that drives experiments, projects, and research in the lab. Many times software belongs to the project/research group, so there's likely a project github organization where the code naturally resides. This is sort of a consequence of labs becoming more and more multi-disciplined, i.e. the science missions of labs like SLAC and Fermilab are no longer aligned primarily around their accelerators.
OSTI is supposed to maintain an index of that software if it's reasonably important, but it's not really enforced.
PS: If someone from USDS/data.gov/18f can and would like to help out with this in any way, I'd be happy to collaborate!
I think a lot of progressive cities are already way ahead of the federal government on this one.